Executive brief
Snipe-IT is an open-source IT asset management platform used to track and manage company hardware and software inventory. A flaw in its permission system allows employees with basic asset file permissions to upload and delete file attachments on shared Asset Model records without proper authorization, potentially affecting multiple companies on the same installation. This bypasses the intended admin-controlled restrictions on file management for the shared asset model catalog.
Technical details
The vulnerability is a broken access control (CWE-284, CWE-863) in the AssetModelPolicy::files() method, which cascades permission checks from the routine assets.files permission instead of enforcing the dedicated models.files permission. The policy incorrectly allows write actions (upload, delete) to Asset Model file attachments based on a read permission, because both read and write operations in the UploadedFilesController use the same undifferentiated 'files' ability. Authentication is required (any authenticated user with assets.files permission), but the attack is network-accessible with no user interaction. An attacker can mutate file attachments across company boundaries since Asset Models lack company-scoping. The vulnerability was patched in version 8.7.0 by introducing a separate manageFiles() ability for write actions.
Affected products
- Snipe-IT Snipe-IT <8.7.0
Timeline
- 2026-08-24: disclosed: GHSA-rhrf-7x22-x2rj published on GitHub
- 2026-09-09: patched: Version 8.7.0 released with fix
- 2026-09-09: advisory: CVE-2026-86774 and NVD entry published